discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

A high-severity remote code execution (RCE) vulnerability in Microsoft SharePoint Server (CVE-2026-45659) has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, despite Microsoft's earlier "Exploitation Less Likely" assessment.

By Ravie Lakshmanan·Jul 2·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Image: thehackernews.com

CISA has flagged a critical SharePoint RCE flaw, CVE-2026-45659, for active exploitation, urging federal agencies to patch immediately. This comes after Microsoft recently uncovered two distinct threat actors, including Storm-2603, simultaneously exploiting vulnerabilities in SharePoint environments, highlighting the complex and persistent nature of modern cyberattacks.

Why it matters

This story matters to security professionals because it highlights the immediate threat posed by actively exploited vulnerabilities in widely used enterprise software like SharePoint, underscoring the urgency of patching and the sophisticated tactics employed by threat actors to maintain persistent access.

Imagine a secret door in a big office building (SharePoint) that bad guys found a way to open, even though the building managers (Microsoft) thought it was pretty secure. Now, a special security team (CISA) is telling everyone to quickly fix that door because bad guys are already using it to sneak in and cause trouble. It's like a game of hide-and-seek where the bad guys are very tricky.

Analysis

The Actively Exploited SharePoint Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a high-severity vulnerability, CVE-2026-45659, affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, with a CVSS score of 8.8, is categorized as a remote code execution (RCE) vulnerability, specifically arising from the deserialization of untrusted data. Microsoft had previously issued a patch for this issue in May 2026, covering SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.

Notably, Microsoft's initial assessment had tagged this flaw with an "Exploitation Less Likely" rating. However, CISA's decision to include it in the KEV catalog directly contradicts this, citing clear evidence of active exploitation in the wild. The vulnerability can be triggered by any authenticated attacker with a minimum of Site Member permissions, meaning it does not require administrative or elevated privileges, making it a significant threat vector for organizations utilizing SharePoint.

CISA's Urgent Directive and Unknowns

CISA's inclusion of CVE-2026-45659 in its KEV catalog serves as a critical alert, particularly for Federal Civilian Executive Branch (FCEB) agencies. These agencies are now mandated to apply the necessary fixes by July 4, 2026, emphasizing the immediate and severe risk posed by the vulnerability. This directive underscores the urgency for all organizations, not just federal entities, to prioritize patching their SharePoint environments.

Despite the confirmation of active exploitation, the article notes that specific details regarding how the vulnerability is being exploited, the identities of the threat actors involved, and their ultimate objectives remain largely unknown. This lack of detailed intelligence can complicate defensive efforts, as security teams must act swiftly based on the confirmed threat without full insight into the attack methodologies.

Broader Threat Landscape: Parallel Attacks

The context of this SharePoint RCE vulnerability is further complicated by Microsoft's recent revelation of parallel threat activity. Late last month, during a routine ransomware investigation, Microsoft uncovered two unrelated threat actors operating simultaneously within the same network. These actors employed deliberate techniques to establish persistent access and complicate incident response efforts, highlighting a sophisticated and multi-layered approach to cyberattacks.

One of these attack clusters has been attributed to Storm-2603, a known threat actor notorious for deploying Warlock ransomware, often by exploiting known vulnerabilities in on-premises SharePoint servers since mid-2025. While the initial access in this specific parallel incident was likely through a different flaw (CVE-2025-11371 impacting Gladinet Triofox), Storm-2603's historical focus on SharePoint underscores the platform's attractiveness to attackers. The group utilized tools like Velociraptor, established multiple remote access channels via Cloudflare tunneling, Zoho Assist, and SSH, and escalated privileges by creating new administrator accounts, even tampering with endpoint security protections. The co-existence of a second, unrelated threat actor using DLL side-loading and custom backdoors further illustrates the complexity, making attribution and comprehensive remediation exceptionally challenging for affected organizations.

Key points

  • CVE-2026-45659, a high-severity RCE flaw in Microsoft SharePoint Server, has been added to CISA's KEV catalog.
  • The vulnerability, stemming from deserialization of untrusted data, allows authenticated attackers with Site Member permissions to execute code remotely.
  • Microsoft had previously assessed the flaw as "Exploitation Less Likely" but patched it in May 2026.
  • CISA mandates Federal Civilian Executive Branch agencies to apply fixes by July 4, 2026, due to active exploitation.
  • Microsoft recently uncovered two distinct threat actors, including Storm-2603, simultaneously exploiting vulnerabilities in SharePoint environments, using advanced techniques to maintain persistence.
The Upside

The rapid addition of CVE-2026-45659 to CISA's KEV catalog ensures that federal agencies are immediately alerted and mandated to apply patches, potentially limiting the scope and impact of ongoing exploitation. Microsoft's detailed reporting on parallel threat activity also provides valuable intelligence for organizations to enhance their defensive strategies against sophisticated, multi-pronged attacks.

The Downside

Despite Microsoft's patch availability since May 2026, the active exploitation of CVE-2026-45659 indicates that many organizations may still be vulnerable, leaving them exposed to remote code execution. The discovery of multiple, unrelated threat actors operating simultaneously within compromised networks suggests a highly complex and persistent threat landscape, making detection and complete remediation exceptionally challenging for security teams.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityvulnerabilitymicrosoftsharepointransomwareremote-code-executionthreat-intelligenceunited-states

Author

Ravie Lakshmanan

Intelligence analysis by

Gemini 2.5 Flash

Published

Jul 2, 2026

Source

thehackernews.com

Share

Topics

securityvulnerabilitymicrosoftsharepointransomwareremote-code-executionthreat-intelligenceunited-states

Related

More from this desk

Aug 17·bleepingcomputer.com

Microsoft Confirms GitHub is Down Worldwide

GitHub is experiencing a widespread outage, causing errors across the website, API, Actions, Pull Requests, and other services. Microsoft confirmed the outage and is investigating the cause.

Aug 17·bleepingcomputer.com

Certighost and the Privilege Hiding in Your Certificate Authority

A vulnerability in the Certification Authority (CA) in Active Directory environments allows a low-privileged user to obtain a valid authentication certificate for a Domain Controller, which can be used to become the Domain Controller. This is a trust-validation problem th…

Aug 17·thehackernews.com

Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

This week's cybersecurity news includes suspected China APT behind VMware exploitation, Apple macOS flaw exploited to drop crypto miner, Lazarus Group exploiting Windows 0-day, GeoServer patches critical flaw under attack, and Amnesia Stealer targeting macOS users.

Aug 17·bleepingcomputer.com

Windows Server 2022 reaches end of mainstream support in 60 days

Microsoft warns IT admins that Windows Server 2022 mainstream support ends October 13, 2026, shifting to extended security updates through October 14, 2031.